> Source: [sk122973](https://support.checkpoint.com/results/sk/sk122973)

# sk122973 - Improved handling of trusted CAs certificates when HTTPS inspection is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk122973 |
| Date Created | 2018-02-14 |
| Last Modified | 2019-05-07 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Websites that use "Staat der Nederlanden Root CA - G2" certificate, fail to open with HTTPS Inspection.  

* Downloading the "Staat der Nederlanden Root CA - G2" certificate and importing it manually into the Trusted CA List ('SmartConsole \> HTTPS Inspection \> Advanced \> Trusted CA \> Import') resolves the issue.  

  **Note:** Use "Update certificate list" option.  

* Debug of WSTLSD daemon (as per [sk105559](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105559)) shows:  
  ***cptls_Validation::CallBackOnFailed: result: -1001, error_level: 0
  cptls_Validation: Chain is NOT trusted !!***
* Examples of sites that use "Staat der Nederlanden Root CA - G2" certificate:  
  https://webmail.kpnmail.nl  
  https://www.belastingdienst.nl  
  https://mijn.kadaster.nl  
  https://tenderned.nl  
  https://www.overheid.nl  
  https://geodata.nationaalgeoregister.nl  
  https://www.bodemplus.nl

## Cause

The Trusted CA list is held on the Security Gateway, and due to a change in the list, it fails to correctly read the "Staat der Nederlanden Root CA - G2" certificate. As a result, it displays the certificate as "Not Trusted".

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
